CVE-2026-81320: Red Hat Build Of Apache Camel - Hawtio 4

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting.

Affected products

  • Red Hat Red Hat Build Of Apache Camel - Hawtio 4

Published 2026-09-15. Last modified 2026-09-17.